Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)) — Vulnerability Class 21532

21532 vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2022-27845 WordPress Plausible Analytics plugin <= 1.2.2 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability — Plausible Analytics (WordPress plugin) 4.8 Medium2022-04-11
CVE-2022-22571 Incapptic Connect 跨站脚本漏洞 — Ivanti Incapptic Connect 4.8 -2022-04-11
CVE-2021-36893 WordPress Responsive Tabs plugin <= 4.0.5 - Cross-Site Scripting (XSS) vulnerability — Responsive Tabs (WordPress plugin) 4.8 Medium2022-04-11
CVE-2021-36846 WordPress Chaty plugin <= 2.8.3 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability — Chaty (WordPress plugin) 4.8 Medium2022-04-11
CVE-2021-36896 WordPress Pricing Table plugin <= 1.5.2 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability — Pricing Table (WordPress plugin) 4.8 Medium2022-04-11
CVE-2021-36848 WordPress Social Media Feather plugin <= 2.0.4 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability — Social Media Feather (WordPress plugin) 3.4 Low2022-04-11
CVE-2021-36910 WordPress WP-Appbox plugin <= 4.3.20 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability — WP-Appbox (WordPress plugin) 3.4 Low2022-04-11
CVE-2022-1007 Advanced Booking Calendar < 1.7.1 - Reflected Cross-Site Scripting — Advanced Booking Calendar 6.1 -2022-04-11
CVE-2022-0969 Image optimization & Lazy Load < 3.3.2 - Admin+ Stored Cross-Site Scripting — Image optimization & Lazy Load by Optimole 4.8 -2022-04-11
CVE-2022-0892 Export All URLs < 4.2 - Reflected Cross-Site Scripting — Export All URLs 6.1 -2022-04-11
CVE-2022-0840 Easy Social Icons < 3.2.1 - Admin+ Stored Cross-Site Scripting in add icon — Easy Social Icons 4.8 -2022-04-11
CVE-2022-0728 Easy Smooth Scroll Links < 2.23.1 - Admin+ Stored Cross-Site Scripting — Easy Smooth Scroll Links 4.8 -2022-04-11
CVE-2022-0531 WPvivid Backup and Migration Plugin < 0.9.70 - Reflected Cross-Site Scripting — Migration, Backup, Staging – WPvivid 6.1 -2022-04-11
CVE-2022-0471 Favicon by RealFaviconGenerator < 1.3.23 - Reflected Cross-Site Scripting — Favicon by RealFaviconGenerator 6.1 -2022-04-11
CVE-2022-0447 Post Grid < 2.1.16 - Reflected Cross-Site Scripting via post_types — Post Grid 5.4 -2022-04-11
CVE-2022-0314 Nimble Page Builder < 3.2.2 - Reflected Cross-Site Scripting — Nimble Page Builder 6.1 -2022-04-11
CVE-2022-0271 LearnPress < 4.1.6 - Reflected Cross-Site Scripting — LearnPress – WordPress LMS Plugin 6.1 -2022-04-11
CVE-2021-25090 GridKit Portfolio < 2.1.0 - Subscriber+ Stored Cross-Site Scripting — Portfolio Gallery, Product Catalog – Grid KIT Portfolio 4.1 -2022-04-11
CVE-2021-24987 Super Socializer < 7.13.30 - Reflected Cross-Site Scripting — Social Share, Social Login and Social Comments Plugin – Super Socializer 6.1 -2022-04-11
CVE-2021-24986 Post Grid < 2.1.16 - Reflected Cross-Site Scripting via keyword — Post Grid 6.1 -2022-04-11
CVE-2022-0936 Cross-site Scripting (XSS) - Stored in autolab/autolab — autolab/autolab 5.4 -2022-04-11
CVE-2022-1291 XSS vulnerability with default `onCellHtmlData` function in hhurz/tableexport.jquery.plugin — hhurz/tableexport.jquery.plugin 6.1 -2022-04-10
CVE-2022-1290 Stored XSS in "Name", "Group Name" & "Title" in polonel/trudesk — polonel/trudesk 5.4 -2022-04-10
CVE-2022-1288 School Club Application System cross site scripting — School Club Application System 4.3 Medium2022-04-09
CVE-2022-20741 Cisco Secure Network Analytics Network Diagrams Application Cross-Site Scripting Vulnerability — Cisco Secure Network Analytics 5.4 Medium2022-04-06
CVE-2022-20781 Cisco Web Security Appliance Stored Cross-Site Scripting Vulnerability — Cisco Web Security Appliance (WSA) 5.4 Medium2022-04-06
CVE-2022-1234 XSS in livehelperchat in livehelperchat/livehelperchat — livehelperchat/livehelperchat 8.8 -2022-04-06
CVE-2022-24811 Cross-site Scripting in Combodo iTop — iTop 5.4 Medium2022-04-05
CVE-2022-28650 JetBrains YouTrack 跨站脚本漏洞 — YouTrack 7.3 High2022-04-05
CVE-2022-0602 Cross-site Scripting (XSS) - DOM in tastyigniter/tastyigniter — tastyigniter/tastyigniter 5.4 -2022-04-05

Vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)) represent 21532 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.